Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20110321214927.GF11269@uio.no>
Date: Mon, 21 Mar 2011 22:49:27 +0100
From: "Steinar H. Gunderson" <sgunderson@...foot.com>
To: Josh Bressers <bressers@...hat.com>
Cc: oss-security@...ts.openwall.com, team@...urity.debian.org
Subject: Re: CVE request: MPM-ITK module for Apache HTTPD

On Mon, Mar 21, 2011 at 04:24:38PM -0400, Josh Bressers wrote:
>> In certain configurations, the MPM-ITK module for Apache HTTPD serves
>> a
>> request as root user instead of the run user configured in the HTTPD
>> configuration:
>> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=618857
> Please use CVE-2011-1176

Thanks. Here are the relevant announcements (with patches):

http://lists.err.no/pipermail/mpm-itk/2011-March/000393.html
http://lists.err.no/pipermail/mpm-itk/2011-March/000394.html

/* Steinar */
-- 
Homepage: http://www.sesse.net/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.